JetBrains Cadence Breach Exposes AWS Credentials via TeamCity Exploit
Attackers breached JetBrains' Cadence infrastructure by exploiting an unpatched TeamCity vulnerability. The company urges all users to rotate credentials immediately.
TL;DR
- Threat actors exploited a critical TeamCity flaw to access JetBrains' internal systems.
- The breach targeted Cadence, exposing AWS credentials and execution secrets.
- JetBrains advises immediate credential revocation and rotation for all Cadence users.
- Unpatched instances of TeamCity were the initial attack vector.
- Organizations using Cadence must audit and secure their cloud configurations.
JetBrains has confirmed a security breach affecting its Cadence workflow platform, stemming from attackers exploiting a known critical vulnerability in its TeamCity build system. The incident resulted in unauthorized access to internal systems and the exposure of sensitive AWS credentials.
In response, JetBrains is advising all Cadence users to immediately revoke and rotate any credentials or secrets that may have been used in Cadence executions. This action is essential to mitigate potential abuse of exposed cloud resources and maintain secure operations.
Vulnerability Exploitation
- Attackers leveraged a recently disclosed critical vulnerability in TeamCity to gain initial access.
- The unpatched nature of the affected TeamCity instance enabled deeper infiltration into JetBrains' environment.
- Exploitation led directly to the compromise of Cadence-related infrastructure and associated AWS credentials.
Impact and Response
- Sensitive execution secrets and cloud credentials were accessed during the breach.
- JetBrains issued an urgent advisory recommending full credential rotation for Cadence users.
- Organizations are advised to audit their AWS environments for signs of unauthorized activity.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.